Vulnerability GHSA-9xm2-gw56-wj7m
Medium Risk
MEDIUM RISK
CVSS Score: 6.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 23, 2026 at 03:32 PM UTC
OpenShift Cluster Logging Operator missing authorization flaw
<0.0.0-20260804174055-1864c2a9851d
<0.0.0-20260804174055-1864c2a9851d
Summary
OpenShift Cluster Logging Operator missing authorization flaw
Details
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
Impacted packages
Timeline
Published
3 months ago
June 23, 2026 at 03:32 PM UTC
Last Modified
3 days ago
September 24, 2026 at 07:15 PM UTC